Unrated severityNVD Advisory· Published May 10, 2018· Updated Aug 5, 2024
CVE-2018-1118
CVE-2018-1118
Description
Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
Affected products
18- osv-coords17 versionspkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweedpkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015pkg:rpm/suse/kernel-livepatch-SLE15_Update_1&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015pkg:rpm/suse/kernel-vanilla&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015pkg:rpm/suse/kernel-zfcpdump&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
< 5.14.6-1.4+ 16 more
- (no CPE)range: < 5.14.6-1.4
- (no CPE)range: < 4.12.14-5.8.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 1-1.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-5.8.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-5.8.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- (no CPE)range: < 4.12.14-25.3.1
- kernel/vhostv5Range: since 4.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- access.redhat.com/errata/RHSA-2018:2948mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:3083mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:3096mitrevendor-advisoryx_refsource_REDHAT
- usn.ubuntu.com/3762-1/mitrevendor-advisoryx_refsource_UBUNTU
- usn.ubuntu.com/3762-2/mitrevendor-advisoryx_refsource_UBUNTU
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.